Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-9447

Опубликовано: 14 нояб. 2016
Источник: redhat
CVSS3: 7.5
CVSS2: 6.8

Описание

The ROM mappings in the NSF decoder in gstreamer 0.10.x allow remote attackers to cause a denial of service (out-of-bounds read or write) and possibly execute arbitrary code via a crafted NSF music file.

A memory corruption flaw was found in GStreamer's Nintendo NSF music file format decoding plug-in. A remote attacker could use this flaw to cause an application using GStreamer to crash or, potentially, execute arbitrary code with the privileges of the user running the application.

Меры по смягчению последствий

sudo rm /usr/lib*/gstreamer-0.10/libgstnsf.so Please note that this mitigation deletes the vulnerable NSF codec file, which removes the functionality to play Nintendo NSF music files.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5gstreamerNot affected
Red Hat Enterprise Linux 6gstreamerNot affected
Red Hat Enterprise Linux 7gstreamerNot affected
Red Hat Enterprise Linux 7gstreamer1Not affected
Red Hat Enterprise Linux 7gstreamer1-plugins-bad-freeNot affected
Red Hat Enterprise Virtualization 3mingw-virt-viewerWill not fix
Red Hat Enterprise Linux 6gstreamer-plugins-bad-freeFixedRHSA-2016:297421.12.2016
Red Hat Enterprise Linux 7gstreamer-plugins-bad-freeFixedRHSA-2017:001805.01.2017

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1395126gstreamer-plugins-bad-free: Memory corruption flaw in NSF decoder

7.5 High

CVSS3

6.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 8 лет назад

The ROM mappings in the NSF decoder in gstreamer 0.10.x allow remote attackers to cause a denial of service (out-of-bounds read or write) and possibly execute arbitrary code via a crafted NSF music file.

CVSS3: 7.8
nvd
больше 8 лет назад

The ROM mappings in the NSF decoder in gstreamer 0.10.x allow remote attackers to cause a denial of service (out-of-bounds read or write) and possibly execute arbitrary code via a crafted NSF music file.

CVSS3: 7.8
debian
больше 8 лет назад

The ROM mappings in the NSF decoder in gstreamer 0.10.x allow remote a ...

CVSS3: 7.8
github
больше 3 лет назад

The ROM mappings in the NSF decoder in gstreamer 0.10.x allow remote attackers to cause a denial of service (out-of-bounds read or write) and possibly execute arbitrary code via a crafted NSF music file.

oracle-oval
больше 8 лет назад

ELSA-2016-2974: gstreamer-plugins-bad-free security update (IMPORTANT)

7.5 High

CVSS3

6.8 Medium

CVSS2